In traditional cloud hosting, developers rely predominantly on guest OS-level firewalls such as ufw, iptables, or nftables.
However, software-based firewalls have a major architectural vulnerability: during heavy volumetric port scanning or SYN flood attacks, malicious traffic traverses the physical switch, floods the virtual NIC queue, and exhausts the hypervisor’s CPU soft-interrupt (SoftIRQ) cycles, causing latency spikes or service degradation.
To solve this, Netcup equips all Generation 12 (G12) servers (including x86 VPS, ARM, and Root Servers) with a complimentary, enterprise-grade stateful hardware firewall running directly on datacenter top-of-rack switches.
Here is a complete operational blueprint for configuring rules, avoiding the fatal ICMPv6 lockout, and integrating automated defense scripts.
1. Hardware Edge Firewall vs. Guest OS Firewalls
- ✕ Malicious packets must penetrate the network stack and reach the kernel.
- ✕ Heavy port scans generate excessive kernel soft-interrupts.
- ✕ Misconfiguration can freeze the network stack completely.
- ✓ Dropped before reaching the host: 0% CPU & RAM overhead.
- ✓ Stateful tracking: Outbound requests allow return traffic automatically.
- ✓ 500 active rules quota with discrete and range port support.
2. Production-Grade Inbound Rule Blueprint
The golden security principle: Default DROP on all inbound traffic, explicitly allow strictly necessary ports.
Recommended Rule Priority Matrix
Configure rules in SCP sequentially from top to bottom:
| Priority | Direction | Protocol | Source CIDR | Port Range | Action | Essential Purpose & Caveats |
|---|---|---|---|---|---|---|
| 1 | Inbound | TCP | Your.Static.IP/32 | 22 (or custom SSH) | ACCEPT | Restrict administrative SSH exclusively to trusted IPs |
| 2 | Inbound | TCP | 0.0.0.0/0 & ::/0 | 80 | ACCEPT | Public HTTP (required for ACME Let’s Encrypt validation) |
| 3 | Inbound | TCP | 0.0.0.0/0 & ::/0 | 443 | ACCEPT | Public HTTPS secure traffic |
| 4 | Inbound | ICMP | 0.0.0.0/0 | Any | ACCEPT | IPv4 Ping diagnostics and path MTU discovery |
| 5 (Crucial) | Inbound | ICMPv6 | ::/0 | Any | ACCEPT | 🔥 MANDATORY: IPv6 Neighbor Discovery Protocol (NDP) |
| 6 (Catch-all) | Inbound | ALL | 0.0.0.0/0 & ::/0 | Any | DROP | Block all unlisted ports at the datacenter switch |
[!CAUTION]
Deep Dive: The Critical ICMPv6 Neighbor Discovery Trap
Unlike IPv4 (which relies on ARP broadcast), IPv6 uses ICMPv6 Neighbor Solicitation (NS) and Neighbor Advertisement (NA) to resolve link-layer addresses. Netcup’s upstream gateway periodically probes your virtual interface with ICMPv6 NS packets. If you drop ICMPv6, your server cannot answer gateway probes, causing the gateway to flush your IP from its neighbor cache and rendering your IPv6 offline within minutes!
3. Step-by-Step SCP Provisioning
- Log into the Netcup Server Control Panel (SCP).
- Select your instance (
v220xxxxxxxx) from the left-hand navigation. - Click the Network tab in the top navigation bar.
- Select the Firewall sub-tab.
- If inactive, click the green button Activate Firewall (Firewall aktivieren).
- Click Add rule to input each entry:
- Direction:
Inbound - Protocol:
TCP,UDP,ICMP, orICMPv6 - Source IP / Subnet: Standard CIDR format (e.g.
1.2.3.4/32,0.0.0.0/0,::/0) - Port / Range: Single (
22), comma-separated (80,443), or span (8000-8080) - Action:
ACCEPTorDROP
- Direction:
- Click Save changes. Rules propagate to physical switches within 15 seconds.
4. Emergency Lockout Recovery
If you mistakenly lock yourself out of SSH:
Option A: HTML5 VNC Console (Bypasses Network Firewall)
- Go to SCP -> Screen.
- Launch the HTML5 VNC Viewer.
- Because VNC interfaces directly with KVM’s virtual display hardware, it is 100% immune to firewall blocks. Log in as
rootto diagnose.
Option B: Deactivate Firewall via SCP
- In SCP -> Network -> Firewall, click the red Deactivate Firewall button.
- The switch immediately stops filtering, restoring your SSH access instantly so you can correct your whitelist rule.
5. Dual-Layer Defense: Hardware Firewall + Local Fail2ban
While the datacenter firewall stops port scans, legitimate HTTP/HTTPS ports (80/443) require local Layer-7 protection against brute-force and web probing:
# Install Fail2ban on Debian 12 / Ubuntu 24.04
apt update && apt install fail2ban -y
Configure /etc/fail2ban/jail.local:
[DEFAULT]
bantime = 3600
findtime = 600
maxretry = 5
banaction = nftables-multiport
[sshd]
enabled = true
port = 22
[nginx-botsearch]
enabled = true
port = http,https
logpath = /var/log/nginx/access.log
maxretry = 2
Restart Fail2ban:
systemctl restart fail2ban
fail2ban-client status sshd
With this architecture, the datacenter switch drops unauthorized traffic with zero CPU hit, while Fail2ban dynamically neutralizes application-layer attacks.